---
title: "Measuring AI Usage Without Sidelining the Works Council"
source: https://bitvaria.com/en/ki-nutzung-messen-ohne-betriebsrat
---

12\. Sept. 2026 · [AI](https://bitvaria.com/category/ai/)  · 8 min read

# Measuring AI Usage Without Sidelining the Works Council

Which paid AI accounts are being used? Before evaluating usage, check data access, existing works agreements, and any agreement still needed. A sequence for IT and management in Germany.

![Which paid AI accounts are being used? Before evaluating usage, check data access, existing works agreements, and any agreement still needed. A sequence for IT and management in Germany.](https://bitvaria.com/_astro/ki-nutzung-messen-ohne-betriebsrat.BCVf1OGz.jpg)

> **Measuring AI usage with the works council.**
> 
> Where a competent works council exists, Section 87(1) No. 6 BetrVG covers technical systems capable of monitoring employees. The required agreement must be in place before use. Existing agreements may already cover the intended scope. Concealed names and group totals do not replace that check.

How many paid AI accounts are being used? An admin center report can be a starting point for that question. Which evaluations are allowed also depends on the agreements in place at the company.

A list per employee, a departmental usage rate, and a company total differ in how they relate to individuals. The underlying system also matters: which individual records does it retain, and who can access them? Establish that before setting up additional data access.

## What the Works Council Co-Determines

The following steps assume a competent works council exists. Section 87(1) No. 6 of Germany’s Works Constitution Act (BetrVG) covers introducing and using technical systems to monitor employee behavior or performance. The Federal Labour Court looks at their objective capability. The employer does not need to intend such monitoring (BAG, 1 ABR 20/21, para. 30).

A report with usage data per employee can enable that monitoring. Concealing names does not resolve the issue if the records can still be linked to individuals.

The right covers introducing and using the system. Nobody needs to have opened a report yet. The works council can seek an injunction against measures that violate its co-determination rights (BAG, 1 ABR 7/15, para. 35).

If the parties cannot agree, Section 87(2) BetrVG provides for a conciliation committee. Its ruling replaces an agreement between the employer and works council. That does not guarantee that a proposed evaluation can go ahead unchanged.

## Four Steps Before the Planned Use

1.  **Check existing rules.** Which works agreements apply to the system? Do they cover the planned evaluation and its purposes? For companies with multiple establishments, establish which works council body is competent.
2.  **Describe the data access.** Which metrics are needed for which decision? Record the source, links to individuals, reporting level, and access rights. IT, the works council, and those responsible for data protection need the same information.
3.  **Reach the required agreement.** If no suitable agreement exists, it must be reached before the use subject to co-determination begins. A works agreement is jointly adopted and recorded in the required form (Section 77(2) BetrVG). A draft alone is not enough. If the parties cannot agree, the statutory conciliation procedure applies.
4.  **Check the system against the agreement.** Inspect access rights, outputs, and deletion settings. Also check who can change settings or export individual records. This shows whether the system matches the agreed scope.

Data protection needs to be assessed too. A works agreement must also meet applicable data protection requirements. A new evaluation may involve different purposes or access rights from the use already permitted.

## What the Agreement Should Record

For an evaluation supporting a license decision, these points are a starting point:

-   **Purpose:** Which decision should the evaluation support? Explicitly exclude later use for individual performance assessment if that falls outside the agreed purpose.
-   **Reporting level:** Specify the team or department metrics needed. No individual employee rankings. Address identifiable raw data separately from permitted outputs.
-   **Minimum group size:** Define the group size required before figures are released and which additional filters are permitted. Small groups and contextual knowledge can enable inferences about individuals.
-   **Deletion periods:** Specify how long raw data and reports are needed and when they will be deleted.
-   **Access rights:** Identify who may view data, export it, or change settings. This includes who could link records to individuals.

A minimum group size is a technical safeguard. On its own, it does not establish that data is anonymous or an evaluation is lawful.

Microsoft uses a configurable minimum group size of at least five people in Viva Insights. In the Copilot adoption group view, the dashboard hides metrics for groups below the configured minimum size. This is a product setting, not a statutory threshold.

Microsoft 365 has concealed user names in usage reports by default since September 2021. The setting can be changed in the admin center. Check the actual configuration and assigned permissions before relying on that default.

## When a Data Processing Agreement Is Needed

Before exporting data to a service provider, establish which data it will receive and what role it will have. Processing personal data on the company’s behalf requires an agreement under Article 28 GDPR. The company remains the controller for that processing and provides the instructions.

A service provider can also be a controller in its own right for particular processing operations. That depends on its actual activities. The label “vendor” or “auditor” does not decide the issue, as the European Data Protection Board explains in Guidelines 07/2020.

Truly anonymous data falls outside the GDPR. Pseudonyms or grouping records together do not by themselves establish anonymity. Check whether the data relates to identifiable individuals before sharing it.

The processing agreement covers, among other things, purpose, duration, data types, rights, and obligations. This includes instructions, confidentiality, safeguards, and rules for further processors. Article 28 also requires support with data subject rights, verification arrangements, and rules for deletion or return. This is a selection; the linked provision contains the full requirements.

If an agreement already exists with Microsoft or another provider, check whether it covers the intended processing. The contract does not replace assessing the company’s legal basis for processing the data in the first place.

## What Needs to Be Clear Before Starting

Three things can be prepared for the next discussion: the metrics needed, the data access they require, and the rules already in place. They provide a concrete basis for checking what still needs agreement or technical restrictions.

**Before the planned use, the scope and permissions must be clear. The required agreement must be in place.**

What a usage figure can tell a company about its next license decision is the next question. See [Paying Per License, Using Per Task](https://bitvaria.com/en/bezahlt-pro-lizenz-genutzt-pro-aufgabe).

## Frequently Asked Questions

**Is measuring AI usage subject to co-determination in Germany?** Where a competent works council exists, Section 87(1) No. 6 BetrVG is relevant. It covers technical systems capable of monitoring employee behavior or performance. An intention to monitor employees is not required. Check with the competent works council which existing agreements cover the planned use.

**When must the works council be involved?** The right covers introducing and using a technical system capable of monitoring employees. It does not arise only when someone opens a report. The required agreement must be in place before the planned use. A draft works agreement is not enough.

**What should a works agreement cover for usage reporting?** Relevant points include purpose, reporting level, minimum group size, deletion periods, and access rights. Describe identifiable raw data separately from the metrics released. Which provisions are necessary and permissible depends on the specific use.

**Are concealed names or aggregated figures sufficient?** Concealed names may still be attributable to individuals. Even with aggregated output, check the raw data and other reporting functions of the system. A minimum group size is a safeguard, not blanket evidence of anonymity or lawful use.

## Sources

-   Introduction, use, and conciliation: [Section 87 BetrVG](https://www.gesetze-im-internet.de/betrvg/__87.html). Concluding works agreements: [Section 77(2) BetrVG](https://www.gesetze-im-internet.de/betrvg/__77.html).
-   Competence across multiple establishments: [Section 50 BetrVG](https://www.gesetze-im-internet.de/betrvg/__50.html).
-   Objective monitoring capability, regardless of intent: [BAG, 8 March 2022, 1 ABR 20/21, para. 30](https://www.bundesarbeitsgericht.de/entscheidung/1-abr-20-21/).
-   Identifiability, group data, and injunctions: [BAG, 13 December 2016, 1 ABR 7/15, paras. 27 and 35](https://www.bundesarbeitsgericht.de/entscheidung/1-abr-7-15/).
-   Anonymity, lawful processing, and processors: [GDPR, Recital 26 and Articles 6, 28, and 88](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A32016R0679).
-   Controller and processor roles: [European Data Protection Board, Guidelines 07/2020, paras. 76 and 82](https://www.edpb.europa.eu/system/files/documents/2023-10/EDPB_guidelines_202007_controllerprocessor_final_en.pdf).
-   User names concealed by default since 1 September 2021 and changing that setting: [Microsoft Learn, Reports show anonymous user names](https://learn.microsoft.com/en-us/troubleshoot/microsoft-365/admin/miscellaneous/reports-show-anonymous-user-name).
-   Minimum group size: [Microsoft Learn, Viva Insights privacy settings](https://learn.microsoft.com/en-us/viva/insights/advanced/setup-maint/privacy-settings). Hiding small groups: [Microsoft Learn, Copilot Dashboard](https://learn.microsoft.com/en-us/viva/insights/org-team-insights/copilot-dashboard).

* * *

*Related: [Residency Is Not Jurisdiction](https://bitvaria.com/en/residenz-ist-nicht-jurisdiktion) and [What Happens If the Provider Goes Away](https://bitvaria.com/en/was-passiert-wenn-der-dienstleister-wegfaellt).*

-   [ki](https://bitvaria.com/tag/ki/)
-   [mitbestimmung](https://bitvaria.com/tag/mitbestimmung/)
-   [datenschutz](https://bitvaria.com/tag/datenschutz/)
-   [mittelstand](https://bitvaria.com/tag/mittelstand/)
-   [compliance](https://bitvaria.com/tag/compliance/)

Share:

[Back to Blog](https://bitvaria.com/blog/)
